mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-18 23:09:29 +02:00
crypto: qce - Remove unsafe/deprecated algorithms
Remove algorithms that are either unsafe or deprecated and have no in-kernel users that cannot be served by the ARM CE implementations. AES-ECB reveals plaintext patterns (identical plaintext blocks produce identical ciphertext blocks) and should not be exposed as a hardware- accelerated primitive. DES, Triple DES and HMAC-SHA1 have been deprecated for years. Remove sha1, ecb(aes), ecb(des), cbc(des), ecb(des3_ede), cbc(des3_ede), hmac(sha1) and all AEAD variants built on these primitives as well as authenc(hmac(sha256),cbc(des)). Also clean up the - now dead - code, flags and constants. Cc: stable@vger.kernel.org Acked-by: Eric Biggers <ebiggers@kernel.org> Tested-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com> Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
committed by
Herbert Xu
parent
c5bcb084a9
commit
7e28b0a5c4
@@ -9,8 +9,6 @@
|
||||
#include <crypto/gcm.h>
|
||||
#include <crypto/authenc.h>
|
||||
#include <crypto/internal/aead.h>
|
||||
#include <crypto/internal/des.h>
|
||||
#include <crypto/sha1.h>
|
||||
#include <crypto/sha2.h>
|
||||
#include <crypto/scatterwalk.h>
|
||||
#include "aead.h"
|
||||
@@ -592,7 +590,6 @@ static int qce_aead_setkey(struct crypto_aead *tfm, const u8 *key, unsigned int
|
||||
struct qce_aead_ctx *ctx = crypto_aead_ctx(tfm);
|
||||
struct crypto_authenc_keys authenc_keys;
|
||||
unsigned long flags = to_aead_tmpl(tfm)->alg_flags;
|
||||
u32 _key[6];
|
||||
int err;
|
||||
|
||||
err = crypto_authenc_extractkeys(&authenc_keys, key, keylen);
|
||||
@@ -603,26 +600,7 @@ static int qce_aead_setkey(struct crypto_aead *tfm, const u8 *key, unsigned int
|
||||
authenc_keys.authkeylen > QCE_MAX_KEY_SIZE)
|
||||
return -EINVAL;
|
||||
|
||||
if (IS_DES(flags)) {
|
||||
err = verify_aead_des_key(tfm, authenc_keys.enckey, authenc_keys.enckeylen);
|
||||
if (err)
|
||||
return err;
|
||||
} else if (IS_3DES(flags)) {
|
||||
err = verify_aead_des3_key(tfm, authenc_keys.enckey, authenc_keys.enckeylen);
|
||||
if (err)
|
||||
return err;
|
||||
/*
|
||||
* The crypto engine does not support any two keys
|
||||
* being the same for triple des algorithms. The
|
||||
* verify_skcipher_des3_key does not check for all the
|
||||
* below conditions. Schedule fallback in this case.
|
||||
*/
|
||||
memcpy(_key, authenc_keys.enckey, DES3_EDE_KEY_SIZE);
|
||||
if (!((_key[0] ^ _key[2]) | (_key[1] ^ _key[3])) ||
|
||||
!((_key[2] ^ _key[4]) | (_key[3] ^ _key[5])) ||
|
||||
!((_key[0] ^ _key[4]) | (_key[1] ^ _key[5])))
|
||||
ctx->need_fallback = true;
|
||||
} else if (IS_AES(flags)) {
|
||||
if (IS_AES(flags)) {
|
||||
/* No random key sizes */
|
||||
if (authenc_keys.enckeylen != AES_KEYSIZE_128 &&
|
||||
authenc_keys.enckeylen != AES_KEYSIZE_192 &&
|
||||
@@ -693,38 +671,6 @@ struct qce_aead_def {
|
||||
};
|
||||
|
||||
static const struct qce_aead_def aead_def[] = {
|
||||
{
|
||||
.flags = QCE_ALG_DES | QCE_MODE_CBC | QCE_HASH_SHA1_HMAC,
|
||||
.name = "authenc(hmac(sha1),cbc(des))",
|
||||
.drv_name = "authenc-hmac-sha1-cbc-des-qce",
|
||||
.blocksize = DES_BLOCK_SIZE,
|
||||
.ivsize = DES_BLOCK_SIZE,
|
||||
.maxauthsize = SHA1_DIGEST_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_3DES | QCE_MODE_CBC | QCE_HASH_SHA1_HMAC,
|
||||
.name = "authenc(hmac(sha1),cbc(des3_ede))",
|
||||
.drv_name = "authenc-hmac-sha1-cbc-3des-qce",
|
||||
.blocksize = DES3_EDE_BLOCK_SIZE,
|
||||
.ivsize = DES3_EDE_BLOCK_SIZE,
|
||||
.maxauthsize = SHA1_DIGEST_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_DES | QCE_MODE_CBC | QCE_HASH_SHA256_HMAC,
|
||||
.name = "authenc(hmac(sha256),cbc(des))",
|
||||
.drv_name = "authenc-hmac-sha256-cbc-des-qce",
|
||||
.blocksize = DES_BLOCK_SIZE,
|
||||
.ivsize = DES_BLOCK_SIZE,
|
||||
.maxauthsize = SHA256_DIGEST_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_3DES | QCE_MODE_CBC | QCE_HASH_SHA256_HMAC,
|
||||
.name = "authenc(hmac(sha256),cbc(des3_ede))",
|
||||
.drv_name = "authenc-hmac-sha256-cbc-3des-qce",
|
||||
.blocksize = DES3_EDE_BLOCK_SIZE,
|
||||
.ivsize = DES3_EDE_BLOCK_SIZE,
|
||||
.maxauthsize = SHA256_DIGEST_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_AES | QCE_MODE_CBC | QCE_HASH_SHA256_HMAC,
|
||||
.name = "authenc(hmac(sha256),cbc(aes))",
|
||||
|
||||
+12
-43
@@ -8,7 +8,6 @@
|
||||
#include <linux/interrupt.h>
|
||||
#include <linux/types.h>
|
||||
#include <crypto/scatterwalk.h>
|
||||
#include <crypto/sha1.h>
|
||||
#include <crypto/sha2.h>
|
||||
|
||||
#include "cipher.h"
|
||||
@@ -115,18 +114,16 @@ static u32 qce_auth_cfg(unsigned long flags, u32 key_size, u32 auth_size)
|
||||
cfg |= AUTH_KEY_SZ_AES256 << AUTH_KEY_SIZE_SHIFT;
|
||||
}
|
||||
|
||||
if (IS_SHA1(flags) || IS_SHA1_HMAC(flags))
|
||||
cfg |= AUTH_SIZE_SHA1 << AUTH_SIZE_SHIFT;
|
||||
else if (IS_SHA256(flags) || IS_SHA256_HMAC(flags))
|
||||
if (IS_SHA256(flags) || IS_SHA256_HMAC(flags))
|
||||
cfg |= AUTH_SIZE_SHA256 << AUTH_SIZE_SHIFT;
|
||||
else if (IS_CMAC(flags))
|
||||
cfg |= AUTH_SIZE_ENUM_16_BYTES << AUTH_SIZE_SHIFT;
|
||||
else if (IS_CCM(flags))
|
||||
cfg |= (auth_size - 1) << AUTH_SIZE_SHIFT;
|
||||
|
||||
if (IS_SHA1(flags) || IS_SHA256(flags))
|
||||
if (IS_SHA256(flags))
|
||||
cfg |= AUTH_MODE_HASH << AUTH_MODE_SHIFT;
|
||||
else if (IS_SHA1_HMAC(flags) || IS_SHA256_HMAC(flags))
|
||||
else if (IS_SHA256_HMAC(flags))
|
||||
cfg |= AUTH_MODE_HMAC << AUTH_MODE_SHIFT;
|
||||
else if (IS_CCM(flags))
|
||||
cfg |= AUTH_MODE_CCM << AUTH_MODE_SHIFT;
|
||||
@@ -191,7 +188,7 @@ static int qce_setup_regs_ahash(struct crypto_async_request *async_req)
|
||||
else
|
||||
qce_cpu_to_be32p_array(auth, rctx->digest, digestsize);
|
||||
|
||||
iv_words = (IS_SHA1(rctx->flags) || IS_SHA1_HMAC(rctx->flags)) ? 5 : 8;
|
||||
iv_words = 8;
|
||||
qce_write_array(qce, REG_AUTH_IV0, (u32 *)auth, iv_words);
|
||||
|
||||
if (rctx->first_blk)
|
||||
@@ -243,19 +240,8 @@ static u32 qce_encr_cfg(unsigned long flags, u32 aes_key_size)
|
||||
|
||||
if (IS_AES(flags))
|
||||
cfg |= ENCR_ALG_AES << ENCR_ALG_SHIFT;
|
||||
else if (IS_DES(flags) || IS_3DES(flags))
|
||||
cfg |= ENCR_ALG_DES << ENCR_ALG_SHIFT;
|
||||
|
||||
if (IS_DES(flags))
|
||||
cfg |= ENCR_KEY_SZ_DES << ENCR_KEY_SZ_SHIFT;
|
||||
|
||||
if (IS_3DES(flags))
|
||||
cfg |= ENCR_KEY_SZ_3DES << ENCR_KEY_SZ_SHIFT;
|
||||
|
||||
switch (flags & QCE_MODE_MASK) {
|
||||
case QCE_MODE_ECB:
|
||||
cfg |= ENCR_MODE_ECB << ENCR_MODE_SHIFT;
|
||||
break;
|
||||
case QCE_MODE_CBC:
|
||||
cfg |= ENCR_MODE_CBC << ENCR_MODE_SHIFT;
|
||||
break;
|
||||
@@ -340,13 +326,7 @@ static int qce_setup_regs_skcipher(struct crypto_async_request *async_req)
|
||||
|
||||
encr_cfg = qce_encr_cfg(flags, keylen);
|
||||
|
||||
if (IS_DES(flags)) {
|
||||
enciv_words = 2;
|
||||
enckey_words = 2;
|
||||
} else if (IS_3DES(flags)) {
|
||||
enciv_words = 2;
|
||||
enckey_words = 6;
|
||||
} else if (IS_AES(flags)) {
|
||||
if (IS_AES(flags)) {
|
||||
if (IS_XTS(flags))
|
||||
qce_xtskey(qce, ctx->enc_key, ctx->enc_keylen,
|
||||
rctx->cryptlen);
|
||||
@@ -357,14 +337,12 @@ static int qce_setup_regs_skcipher(struct crypto_async_request *async_req)
|
||||
|
||||
qce_write_array(qce, REG_ENCR_KEY0, (u32 *)enckey, enckey_words);
|
||||
|
||||
if (!IS_ECB(flags)) {
|
||||
if (IS_XTS(flags))
|
||||
qce_xts_swapiv(enciv, rctx->iv, ivsize);
|
||||
else
|
||||
qce_cpu_to_be32p_array(enciv, rctx->iv, ivsize);
|
||||
if (IS_XTS(flags))
|
||||
qce_xts_swapiv(enciv, rctx->iv, ivsize);
|
||||
else
|
||||
qce_cpu_to_be32p_array(enciv, rctx->iv, ivsize);
|
||||
|
||||
qce_write_array(qce, REG_CNTR0_IV0, (u32 *)enciv, enciv_words);
|
||||
}
|
||||
qce_write_array(qce, REG_CNTR0_IV0, (u32 *)enciv, enciv_words);
|
||||
|
||||
if (IS_ENCRYPT(flags))
|
||||
encr_cfg |= BIT(ENCODE_SHIFT);
|
||||
@@ -393,10 +371,6 @@ static int qce_setup_regs_skcipher(struct crypto_async_request *async_req)
|
||||
#endif
|
||||
|
||||
#ifdef CONFIG_CRYPTO_DEV_QCE_AEAD
|
||||
static const u32 std_iv_sha1[SHA256_DIGEST_SIZE / sizeof(u32)] = {
|
||||
SHA1_H0, SHA1_H1, SHA1_H2, SHA1_H3, SHA1_H4, 0, 0, 0
|
||||
};
|
||||
|
||||
static const u32 std_iv_sha256[SHA256_DIGEST_SIZE / sizeof(u32)] = {
|
||||
SHA256_H0, SHA256_H1, SHA256_H2, SHA256_H3,
|
||||
SHA256_H4, SHA256_H5, SHA256_H6, SHA256_H7
|
||||
@@ -473,13 +447,8 @@ static int qce_setup_regs_aead(struct crypto_async_request *async_req)
|
||||
/* Write initial authentication IV only for HMAC algorithms */
|
||||
if (IS_SHA_HMAC(rctx->flags)) {
|
||||
/* Write default authentication iv */
|
||||
if (IS_SHA1_HMAC(rctx->flags)) {
|
||||
auth_ivsize = SHA1_DIGEST_SIZE;
|
||||
memcpy(authiv, std_iv_sha1, auth_ivsize);
|
||||
} else if (IS_SHA256_HMAC(rctx->flags)) {
|
||||
auth_ivsize = SHA256_DIGEST_SIZE;
|
||||
memcpy(authiv, std_iv_sha256, auth_ivsize);
|
||||
}
|
||||
auth_ivsize = SHA256_DIGEST_SIZE;
|
||||
memcpy(authiv, std_iv_sha256, auth_ivsize);
|
||||
authiv_words = auth_ivsize / sizeof(u32);
|
||||
qce_write_array(qce, REG_AUTH_IV0, (u32 *)authiv, authiv_words);
|
||||
} else if (IS_CCM(rctx->flags)) {
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
|
||||
/* IV length in bytes */
|
||||
#define QCE_AES_IV_LENGTH AES_BLOCK_SIZE
|
||||
/* max of AES_BLOCK_SIZE, DES3_EDE_BLOCK_SIZE */
|
||||
/* max of AES_BLOCK_SIZE */
|
||||
#define QCE_MAX_IV_SIZE AES_BLOCK_SIZE
|
||||
|
||||
/* maximum nonce bytes */
|
||||
@@ -33,14 +33,10 @@
|
||||
#define QCE_MAX_ALIGN_SIZE 64
|
||||
|
||||
/* cipher algorithms */
|
||||
#define QCE_ALG_DES BIT(0)
|
||||
#define QCE_ALG_3DES BIT(1)
|
||||
#define QCE_ALG_AES BIT(2)
|
||||
|
||||
/* hash and hmac algorithms */
|
||||
#define QCE_HASH_SHA1 BIT(3)
|
||||
#define QCE_HASH_SHA256 BIT(4)
|
||||
#define QCE_HASH_SHA1_HMAC BIT(5)
|
||||
#define QCE_HASH_SHA256_HMAC BIT(6)
|
||||
#define QCE_HASH_AES_CMAC BIT(7)
|
||||
|
||||
@@ -58,21 +54,15 @@
|
||||
#define QCE_ENCRYPT BIT(30)
|
||||
#define QCE_DECRYPT BIT(31)
|
||||
|
||||
#define IS_DES(flags) (flags & QCE_ALG_DES)
|
||||
#define IS_3DES(flags) (flags & QCE_ALG_3DES)
|
||||
#define IS_AES(flags) (flags & QCE_ALG_AES)
|
||||
|
||||
#define IS_SHA1(flags) (flags & QCE_HASH_SHA1)
|
||||
#define IS_SHA256(flags) (flags & QCE_HASH_SHA256)
|
||||
#define IS_SHA1_HMAC(flags) (flags & QCE_HASH_SHA1_HMAC)
|
||||
#define IS_SHA256_HMAC(flags) (flags & QCE_HASH_SHA256_HMAC)
|
||||
#define IS_CMAC(flags) (flags & QCE_HASH_AES_CMAC)
|
||||
#define IS_SHA(flags) (IS_SHA1(flags) || IS_SHA256(flags))
|
||||
#define IS_SHA_HMAC(flags) \
|
||||
(IS_SHA1_HMAC(flags) || IS_SHA256_HMAC(flags))
|
||||
#define IS_SHA(flags) IS_SHA256(flags)
|
||||
#define IS_SHA_HMAC(flags) IS_SHA256_HMAC(flags)
|
||||
|
||||
#define IS_CBC(mode) (mode & QCE_MODE_CBC)
|
||||
#define IS_ECB(mode) (mode & QCE_MODE_ECB)
|
||||
#define IS_CTR(mode) (mode & QCE_MODE_CTR)
|
||||
#define IS_XTS(mode) (mode & QCE_MODE_XTS)
|
||||
#define IS_CCM(mode) (mode & QCE_MODE_CCM)
|
||||
|
||||
@@ -203,7 +203,6 @@
|
||||
|
||||
#define AUTH_SIZE_SHIFT 9
|
||||
#define AUTH_SIZE_MASK GENMASK(13, 9)
|
||||
#define AUTH_SIZE_SHA1 0
|
||||
#define AUTH_SIZE_SHA256 1
|
||||
#define AUTH_SIZE_ENUM_1_BYTES 0
|
||||
#define AUTH_SIZE_ENUM_2_BYTES 1
|
||||
@@ -284,15 +283,12 @@
|
||||
|
||||
#define ENCR_KEY_SZ_SHIFT 3
|
||||
#define ENCR_KEY_SZ_MASK GENMASK(5, 3)
|
||||
#define ENCR_KEY_SZ_DES 0
|
||||
#define ENCR_KEY_SZ_3DES 1
|
||||
#define ENCR_KEY_SZ_AES128 0
|
||||
#define ENCR_KEY_SZ_AES256 2
|
||||
|
||||
#define ENCR_ALG_SHIFT 0
|
||||
#define ENCR_ALG_MASK GENMASK(2, 0)
|
||||
#define ENCR_ALG_NONE 0
|
||||
#define ENCR_ALG_DES 1
|
||||
#define ENCR_ALG_AES 2
|
||||
#define ENCR_ALG_KASUMI 4
|
||||
#define ENCR_ALG_SNOW_3G 5
|
||||
|
||||
@@ -25,10 +25,6 @@ struct qce_sha_saved_state {
|
||||
|
||||
static LIST_HEAD(ahash_algs);
|
||||
|
||||
static const u32 std_iv_sha1[SHA256_DIGEST_SIZE / sizeof(u32)] = {
|
||||
SHA1_H0, SHA1_H1, SHA1_H2, SHA1_H3, SHA1_H4, 0, 0, 0
|
||||
};
|
||||
|
||||
static const u32 std_iv_sha256[SHA256_DIGEST_SIZE / sizeof(u32)] = {
|
||||
SHA256_H0, SHA256_H1, SHA256_H2, SHA256_H3,
|
||||
SHA256_H4, SHA256_H5, SHA256_H6, SHA256_H7
|
||||
@@ -328,9 +324,7 @@ static int qce_ahash_hmac_setkey(struct crypto_ahash *tfm, const u8 *key,
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (digestsize == SHA1_DIGEST_SIZE)
|
||||
alg_name = "sha1-qce";
|
||||
else if (digestsize == SHA256_DIGEST_SIZE)
|
||||
if (digestsize == SHA256_DIGEST_SIZE)
|
||||
alg_name = "sha256-qce";
|
||||
else
|
||||
return -EINVAL;
|
||||
@@ -391,15 +385,6 @@ struct qce_ahash_def {
|
||||
};
|
||||
|
||||
static const struct qce_ahash_def ahash_def[] = {
|
||||
{
|
||||
.flags = QCE_HASH_SHA1,
|
||||
.name = "sha1",
|
||||
.drv_name = "sha1-qce",
|
||||
.digestsize = SHA1_DIGEST_SIZE,
|
||||
.blocksize = SHA1_BLOCK_SIZE,
|
||||
.statesize = sizeof(struct qce_sha_saved_state),
|
||||
.std_iv = std_iv_sha1,
|
||||
},
|
||||
{
|
||||
.flags = QCE_HASH_SHA256,
|
||||
.name = "sha256",
|
||||
@@ -409,15 +394,6 @@ static const struct qce_ahash_def ahash_def[] = {
|
||||
.statesize = sizeof(struct qce_sha_saved_state),
|
||||
.std_iv = std_iv_sha256,
|
||||
},
|
||||
{
|
||||
.flags = QCE_HASH_SHA1_HMAC,
|
||||
.name = "hmac(sha1)",
|
||||
.drv_name = "hmac-sha1-qce",
|
||||
.digestsize = SHA1_DIGEST_SIZE,
|
||||
.blocksize = SHA1_BLOCK_SIZE,
|
||||
.statesize = sizeof(struct qce_sha_saved_state),
|
||||
.std_iv = std_iv_sha1,
|
||||
},
|
||||
{
|
||||
.flags = QCE_HASH_SHA256_HMAC,
|
||||
.name = "hmac(sha256)",
|
||||
@@ -455,9 +431,7 @@ static int qce_ahash_register_one(const struct qce_ahash_def *def,
|
||||
alg->halg.digestsize = def->digestsize;
|
||||
alg->halg.statesize = def->statesize;
|
||||
|
||||
if (IS_SHA1(def->flags))
|
||||
tmpl->hash_zero = sha1_zero_message_hash;
|
||||
else if (IS_SHA256(def->flags))
|
||||
if (IS_SHA256(def->flags))
|
||||
tmpl->hash_zero = sha256_zero_message_hash;
|
||||
|
||||
base = &alg->halg.base;
|
||||
|
||||
@@ -7,7 +7,6 @@
|
||||
#define _SHA_H_
|
||||
|
||||
#include <crypto/scatterwalk.h>
|
||||
#include <crypto/sha1.h>
|
||||
#include <crypto/sha2.h>
|
||||
|
||||
#include "common.h"
|
||||
|
||||
@@ -11,7 +11,6 @@
|
||||
#include <linux/types.h>
|
||||
#include <linux/errno.h>
|
||||
#include <crypto/aes.h>
|
||||
#include <crypto/internal/des.h>
|
||||
#include <crypto/internal/skcipher.h>
|
||||
|
||||
#include "cipher.h"
|
||||
@@ -209,51 +208,6 @@ static int qce_skcipher_setkey(struct crypto_skcipher *ablk, const u8 *key,
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int qce_des_setkey(struct crypto_skcipher *ablk, const u8 *key,
|
||||
unsigned int keylen)
|
||||
{
|
||||
struct qce_cipher_ctx *ctx = crypto_skcipher_ctx(ablk);
|
||||
int err;
|
||||
|
||||
err = verify_skcipher_des_key(ablk, key);
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
ctx->enc_keylen = keylen;
|
||||
memcpy(ctx->enc_key, key, keylen);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int qce_des3_setkey(struct crypto_skcipher *ablk, const u8 *key,
|
||||
unsigned int keylen)
|
||||
{
|
||||
struct qce_cipher_ctx *ctx = crypto_skcipher_ctx(ablk);
|
||||
u32 _key[6];
|
||||
int err;
|
||||
|
||||
err = verify_skcipher_des3_key(ablk, key);
|
||||
if (err)
|
||||
return err;
|
||||
|
||||
/*
|
||||
* The crypto engine does not support any two keys
|
||||
* being the same for triple des algorithms. The
|
||||
* verify_skcipher_des3_key does not check for all the
|
||||
* below conditions. Return -ENOKEY in case any two keys
|
||||
* are the same. Revisit to see if a fallback cipher
|
||||
* is needed to handle this condition.
|
||||
*/
|
||||
memcpy(_key, key, DES3_EDE_KEY_SIZE);
|
||||
if (!((_key[0] ^ _key[2]) | (_key[1] ^ _key[3])) ||
|
||||
!((_key[2] ^ _key[4]) | (_key[3] ^ _key[5])) ||
|
||||
!((_key[0] ^ _key[4]) | (_key[1] ^ _key[5])))
|
||||
return -ENOKEY;
|
||||
|
||||
ctx->enc_keylen = keylen;
|
||||
memcpy(ctx->enc_key, key, keylen);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int qce_skcipher_crypt(struct skcipher_request *req, int encrypt)
|
||||
{
|
||||
struct crypto_skcipher *tfm = crypto_skcipher_reqtfm(req);
|
||||
@@ -276,7 +230,7 @@ static int qce_skcipher_crypt(struct skcipher_request *req, int encrypt)
|
||||
* ECB and CBC algorithms require message lengths to be
|
||||
* multiples of block size.
|
||||
*/
|
||||
if (IS_ECB(rctx->flags) || IS_CBC(rctx->flags))
|
||||
if (IS_CBC(rctx->flags))
|
||||
if (!IS_ALIGNED(req->cryptlen, blocksize))
|
||||
return -EINVAL;
|
||||
|
||||
@@ -359,15 +313,6 @@ struct qce_skcipher_def {
|
||||
};
|
||||
|
||||
static const struct qce_skcipher_def skcipher_def[] = {
|
||||
{
|
||||
.flags = QCE_ALG_AES | QCE_MODE_ECB,
|
||||
.name = "ecb(aes)",
|
||||
.drv_name = "ecb-aes-qce",
|
||||
.blocksize = AES_BLOCK_SIZE,
|
||||
.ivsize = 0,
|
||||
.min_keysize = AES_MIN_KEY_SIZE,
|
||||
.max_keysize = AES_MAX_KEY_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_AES | QCE_MODE_CBC,
|
||||
.name = "cbc(aes)",
|
||||
@@ -396,42 +341,6 @@ static const struct qce_skcipher_def skcipher_def[] = {
|
||||
.min_keysize = AES_MIN_KEY_SIZE * 2,
|
||||
.max_keysize = AES_MAX_KEY_SIZE * 2,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_DES | QCE_MODE_ECB,
|
||||
.name = "ecb(des)",
|
||||
.drv_name = "ecb-des-qce",
|
||||
.blocksize = DES_BLOCK_SIZE,
|
||||
.ivsize = 0,
|
||||
.min_keysize = DES_KEY_SIZE,
|
||||
.max_keysize = DES_KEY_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_DES | QCE_MODE_CBC,
|
||||
.name = "cbc(des)",
|
||||
.drv_name = "cbc-des-qce",
|
||||
.blocksize = DES_BLOCK_SIZE,
|
||||
.ivsize = DES_BLOCK_SIZE,
|
||||
.min_keysize = DES_KEY_SIZE,
|
||||
.max_keysize = DES_KEY_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_3DES | QCE_MODE_ECB,
|
||||
.name = "ecb(des3_ede)",
|
||||
.drv_name = "ecb-3des-qce",
|
||||
.blocksize = DES3_EDE_BLOCK_SIZE,
|
||||
.ivsize = 0,
|
||||
.min_keysize = DES3_EDE_KEY_SIZE,
|
||||
.max_keysize = DES3_EDE_KEY_SIZE,
|
||||
},
|
||||
{
|
||||
.flags = QCE_ALG_3DES | QCE_MODE_CBC,
|
||||
.name = "cbc(des3_ede)",
|
||||
.drv_name = "cbc-3des-qce",
|
||||
.blocksize = DES3_EDE_BLOCK_SIZE,
|
||||
.ivsize = DES3_EDE_BLOCK_SIZE,
|
||||
.min_keysize = DES3_EDE_KEY_SIZE,
|
||||
.max_keysize = DES3_EDE_KEY_SIZE,
|
||||
},
|
||||
};
|
||||
|
||||
static int qce_skcipher_register_one(const struct qce_skcipher_def *def,
|
||||
@@ -455,9 +364,7 @@ static int qce_skcipher_register_one(const struct qce_skcipher_def *def,
|
||||
alg->ivsize = def->ivsize;
|
||||
alg->min_keysize = def->min_keysize;
|
||||
alg->max_keysize = def->max_keysize;
|
||||
alg->setkey = IS_3DES(def->flags) ? qce_des3_setkey :
|
||||
IS_DES(def->flags) ? qce_des_setkey :
|
||||
qce_skcipher_setkey;
|
||||
alg->setkey = qce_skcipher_setkey;
|
||||
alg->encrypt = qce_skcipher_encrypt;
|
||||
alg->decrypt = qce_skcipher_decrypt;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user